Skip to main content

AnomalyDetector

Struct AnomalyDetector 

Source
pub struct AnomalyDetector { /* private fields */ }
Expand description

Anomaly detector using z-score sliding windows on harmony dimensions.

Maintains a rolling window of HarmonyVector samples and computes z-scores for each of the 7 numeric dimensions. When a dimension’s z-score exceeds the warning or critical threshold, an AnomalyAlert is generated.

§Example

use wm_substrate::{SubstrateMonitor, anomaly::{AnomalyDetector, AnomalySeverity}};

let monitor = SubstrateMonitor::default();
let mut detector = AnomalyDetector::default();

let hv = monitor.sample();
let alerts = detector.check(&hv);
for alert in &alerts {
    if alert.severity == AnomalySeverity::Critical {
        // Take corrective action
    }
}

Implementations§

Source§

impl AnomalyDetector

Source

pub fn new(config: AnomalyConfig) -> Self

Create a new anomaly detector with the given configuration.

Source

pub fn check(&mut self, hv: &HarmonyVector) -> Vec<AnomalyAlert>

Process a new HarmonyVector sample and return any anomaly alerts.

The sample is added to the rolling window, then z-scores are computed for each dimension. Dimensions with |z| > warning_threshold generate alerts.

Metric values are clamped to valid ranges before being added to the window, preventing poisoned metrics (e.g., negative CPU, f32::MAX) from skewing z-scores.

Note: the current sample is included in the window before computing the z-score, which slightly dampens the score. This is intentional — it prevents a single spike from generating a false positive when the window is large.

Source

pub fn stats(&self, dim: HarmonyDimension) -> (f32, f32, usize)

Get the current rolling statistics for a dimension.

Returns (mean, std_dev, sample_count) for the dimension’s window.

Source

pub const fn alert_count(&self) -> u64

Total alerts detected since creation.

Source

pub const fn sample_count(&self) -> u64

Total samples processed.

Source

pub fn window_len(&self, dim: HarmonyDimension) -> usize

Number of samples in the window for a specific dimension.

Source

pub fn summary(&self) -> Value

Get a JSON summary of the detector’s state.

Trait Implementations§

Source§

impl Default for AnomalyDetector

Source§

fn default() -> Self

Returns the “default value” for a type. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more